CVE-2014-3341: Infoleak
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3341?
CVE-2014-3341 is considered a medium severity vulnerability that allows attackers to enumerate VLANs.
How do I fix CVE-2014-3341?
To fix CVE-2014-3341, upgrade Cisco NX-OS to a version that is later than 7.0(3)N1(1).
What types of devices are affected by CVE-2014-3341?
CVE-2014-3341 affects Cisco Nexus 5000 and 6000 series devices running vulnerable versions of NX-OS.
Can CVE-2014-3341 be exploited remotely?
Yes, CVE-2014-3341 can be exploited remotely by attackers sending specific SNMP requests.
What is the impact of CVE-2014-3341 on network security?
The impact of CVE-2014-3341 is that it allows unauthorized users to gather information about VLAN configurations, which can lead to further attacks.